Pages

Monday, July 20, 2026

When is it over? - Part 2

Remember the Canvas hacking that brought instruction at various universities including UCLA to a halt?

From Inside Higher Ed: Two months after Instructure made a deal with hackers to salvage troves of stolen user data, the company—which owns the popular learning management system Canvas—may have another breach on its hands. And this time, the incident is delaying Instructure’s efforts to be transparent with its customers about their compromised data. 

In May, a criminal extortion group known as ShinyHunters twice hacked Canvas and claimed that it gained access to the personal identifying information of 275 million people across 9,000 institutions. At the time, the company said the leaked information included names, email addresses, student ID numbers and user messages, but it “found no evidence that passwords, dates of birth, government identifiers, or financial information were involved.” 

In the aftermath, Instructure CEO Steve Daly vowed to be “transparent about what happened” and provide K–12 schools and higher education institutions “with information as quickly as we responsibly could.” Over the past two months, Instructure has worked “to conduct a detailed forensic review of the data involved in this incident,” Daly said in a memo last week. On Tuesday, the company was set to deliver to institutions the first wave of data related to the breach. Instead, Daly said Tuesday that the company is “pausing data delivery out of an abundance of caution” after learning that “the third-party platform we’ve selected to deliver your data may have been subject to a security threat.” ...

Full story at https://www.insidehighered.com/news/quick-takes/2026/07/16/another-security-threat-canvas.

No comments: